Re: Cryptsetup and hardware accelerated AES-XTS
Eric Biggers <[email protected]> Sat, 20 Jul 2024 10:36:11 -0700
| Newsgroups | dev.linux.lists.cryptsetup |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Jul 20, 2024 at 12:15:23PM +0000, Maxim Fomin wrote: > Hi! > > Recently linux kernel got[1] faster AES-XTS on modern x86_64 CPUs thanks to VAES and AVX-10/512. I decided to dig deeper into this issue and found the article[2] from 2020 stating that dm-crypt can be configured to use faster (synchronous and hardware accelerated) algorithms with 'capi:' prefix. Can cryptsetup be configured to ask dm-crypt to use hardware accelerated algorithms? > > [1] https://lore.kernel.org/lkml/[email protected]/T/#m83293b2699f9a5da04fc5780ee402191dace3926 > > [2] https://blog.cloudflare.com/speeding-up-linux-disk-encryption/ > > Best regards, > Maxim > You don't need to use "capi:". Just make sure CONFIG_CRYPTO_AES_NI_INTEL=y is enabled in your kernel (which it already should have been since it was needed for AES-NI acceleration before), and the new code will be used automatically if your CPU supports it. - Eric